-
Notifications
You must be signed in to change notification settings - Fork 152
Closed
Description
Current version 6.2.1 of the Respawn package has a security vulnerability because of an old dependency to Microsoft.Data.SqlClient, that has a dependency to System.Drawing.Common@5.0.0.
.NET Core Remote Code Execution Vulnerability (This package is used under: Respawn@6.2.1->Microsoft.Data.SqlClient@4.0.5->System.Configuration.ConfigurationManager@5.0.0->System.Security.Permissions@5.0.0->System.Windows.Extensions@5.0.0->System.Drawing.Common@5.0.0)
Please update to mitigate this vulnerability.
CVE description: https://nvd.nist.gov/vuln/detail/CVE-2021-24112
liborpansky, ldeluigi, sveinungf, michael-wolfenden and ThumbGen
Metadata
Metadata
Assignees
Labels
No labels